86 lines
4.8 KiB
Properties
86 lines
4.8 KiB
Properties
{% raw %}
|
|
# Log4j CUSTOM FILE
|
|
|
|
status = error
|
|
logger.action.name = org.elasticsearch.action
|
|
logger.action.level = debug
|
|
appender.rolling.type = Console
|
|
appender.rolling.name = rolling
|
|
appender.rolling.layout.type = ESJsonLayout
|
|
appender.rolling.layout.type_name = server
|
|
rootLogger.level = info
|
|
rootLogger.appenderRef.rolling.ref = rolling
|
|
appender.deprecation_rolling.type = Console
|
|
appender.deprecation_rolling.name = deprecation_rolling
|
|
appender.deprecation_rolling.layout.type = ESJsonLayout
|
|
appender.deprecation_rolling.layout.type_name = deprecation
|
|
appender.deprecation_rolling.layout.esmessagefields=x-opaque-id
|
|
logger.deprecation.name = org.elasticsearch.deprecation
|
|
logger.deprecation.level = warn
|
|
logger.deprecation.appenderRef.deprecation_rolling.ref = deprecation_rolling
|
|
logger.deprecation.additivity = false
|
|
appender.index_search_slowlog_rolling.type = Console
|
|
appender.index_search_slowlog_rolling.name = index_search_slowlog_rolling
|
|
appender.index_search_slowlog_rolling.layout.type = ESJsonLayout
|
|
appender.index_search_slowlog_rolling.layout.type_name = index_search_slowlog
|
|
appender.index_search_slowlog_rolling.layout.esmessagefields=message,took,took_millis,total_hits,stats,search_type,total_shards,source,id
|
|
logger.index_search_slowlog_rolling.name = index.search.slowlog
|
|
logger.index_search_slowlog_rolling.level = trace
|
|
logger.index_search_slowlog_rolling.appenderRef.index_search_slowlog_rolling.ref = index_search_slowlog_rolling
|
|
logger.index_search_slowlog_rolling.additivity = false
|
|
appender.index_indexing_slowlog_rolling.type = Console
|
|
appender.index_indexing_slowlog_rolling.name = index_indexing_slowlog_rolling
|
|
appender.index_indexing_slowlog_rolling.layout.type = ESJsonLayout
|
|
appender.index_indexing_slowlog_rolling.layout.type_name = index_indexing_slowlog
|
|
appender.index_indexing_slowlog_rolling.layout.esmessagefields=message,took,took_millis,doc_type,id,routing,source
|
|
logger.index_indexing_slowlog.name = index.indexing.slowlog.index
|
|
logger.index_indexing_slowlog.level = trace
|
|
logger.index_indexing_slowlog.appenderRef.index_indexing_slowlog_rolling.ref = index_indexing_slowlog_rolling
|
|
logger.index_indexing_slowlog.additivity = false
|
|
appender.audit_rolling.type = Console
|
|
appender.audit_rolling.name = audit_rolling
|
|
appender.audit_rolling.layout.type = PatternLayout
|
|
appender.audit_rolling.layout.pattern = {\
|
|
"type": "audit", \
|
|
"timestamp":"%d{yyyy-MM-dd'T'HH:mm:ss,SSSZ}"\
|
|
%varsNotEmpty{, "node.name":"%enc{%map{node.name}}{JSON}"}\
|
|
%varsNotEmpty{, "node.id":"%enc{%map{node.id}}{JSON}"}\
|
|
%varsNotEmpty{, "host.name":"%enc{%map{host.name}}{JSON}"}\
|
|
%varsNotEmpty{, "host.ip":"%enc{%map{host.ip}}{JSON}"}\
|
|
%varsNotEmpty{, "event.type":"%enc{%map{event.type}}{JSON}"}\
|
|
%varsNotEmpty{, "event.action":"%enc{%map{event.action}}{JSON}"}\
|
|
%varsNotEmpty{, "user.name":"%enc{%map{user.name}}{JSON}"}\
|
|
%varsNotEmpty{, "user.run_by.name":"%enc{%map{user.run_by.name}}{JSON}"}\
|
|
%varsNotEmpty{, "user.run_as.name":"%enc{%map{user.run_as.name}}{JSON}"}\
|
|
%varsNotEmpty{, "user.realm":"%enc{%map{user.realm}}{JSON}"}\
|
|
%varsNotEmpty{, "user.run_by.realm":"%enc{%map{user.run_by.realm}}{JSON}"}\
|
|
%varsNotEmpty{, "user.run_as.realm":"%enc{%map{user.run_as.realm}}{JSON}"}\
|
|
%varsNotEmpty{, "user.roles":%map{user.roles}}\
|
|
%varsNotEmpty{, "origin.type":"%enc{%map{origin.type}}{JSON}"}\
|
|
%varsNotEmpty{, "origin.address":"%enc{%map{origin.address}}{JSON}"}\
|
|
%varsNotEmpty{, "realm":"%enc{%map{realm}}{JSON}"}\
|
|
%varsNotEmpty{, "url.path":"%enc{%map{url.path}}{JSON}"}\
|
|
%varsNotEmpty{, "url.query":"%enc{%map{url.query}}{JSON}"}\
|
|
%varsNotEmpty{, "request.method":"%enc{%map{request.method}}{JSON}"}\
|
|
%varsNotEmpty{, "request.body":"%enc{%map{request.body}}{JSON}"}\
|
|
%varsNotEmpty{, "request.id":"%enc{%map{request.id}}{JSON}"}\
|
|
%varsNotEmpty{, "action":"%enc{%map{action}}{JSON}"}\
|
|
%varsNotEmpty{, "request.name":"%enc{%map{request.name}}{JSON}"}\
|
|
%varsNotEmpty{, "indices":%map{indices}}\
|
|
%varsNotEmpty{, "opaque_id":"%enc{%map{opaque_id}}{JSON}"}\
|
|
%varsNotEmpty{, "x_forwarded_for":"%enc{%map{x_forwarded_for}}{JSON}"}\
|
|
%varsNotEmpty{, "transport.profile":"%enc{%map{transport.profile}}{JSON}"}\
|
|
%varsNotEmpty{, "rule":"%enc{%map{rule}}{JSON}"}\
|
|
%varsNotEmpty{, "event.category":"%enc{%map{event.category}}{JSON}"}\
|
|
}%n
|
|
logger.xpack_security_audit_logfile.name = org.elasticsearch.xpack.security.audit.logfile.LoggingAuditTrail
|
|
logger.xpack_security_audit_logfile.level = info
|
|
logger.xpack_security_audit_logfile.appenderRef.audit_rolling.ref = audit_rolling
|
|
logger.xpack_security_audit_logfile.additivity = false
|
|
logger.xmlsig.name = org.apache.xml.security.signature.XMLSignature
|
|
logger.xmlsig.level = error
|
|
logger.samlxml_decrypt.name = org.opensaml.xmlsec.encryption.support.Decrypter
|
|
logger.samlxml_decrypt.level = fatal
|
|
logger.saml2_decrypt.name = org.opensaml.saml.saml2.encryption.Decrypter
|
|
logger.saml2_decrypt.level = fatal
|
|
{% endraw %}
|